OpenSSH is the standard command-line tool for opening an encrypted shell or running a command on a remote Linux server. The client supports passwords and several stronger authentication methods, including public-key authentication.
Make a basic connection
Supply the remote account followed by the server name:
ssh user@server.example.comOn the first connection, SSH displays the server's host-key fingerprint. Verify that fingerprint with the server administrator or another trusted source before accepting it. The host key proves which server you reached; accepting an unverified key leaves room for a machine-in-the-middle attack.
Once accepted, the host key is recorded in ~/.ssh/known_hosts. SSH warns and refuses normal authentication if that identity later changes unexpectedly. Investigate that warning instead of deleting the old entry automatically.
The server decides which authentication methods it permits. If password authentication is enabled and no suitable key is available, the client may ask for the remote account's password.
Connect with a key pair
Public-key authentication uses two related files:
- The public key is installed for the remote account, normally in
~/.ssh/authorized_keyson the server. - The private key remains on the client and proves possession of the key pair. It must not be shared.
Create a dedicated Ed25519 key pair and set a passphrase when prompted:
ssh-keygen -t ed25519 -f ~/.ssh/work-example -C "work-example"This produces the private key ~/.ssh/work-example and public key ~/.ssh/work-example.pub. If the server temporarily permits password authentication and ssh-copy-id is installed, append the public key to the remote account with:
ssh-copy-id -i ~/.ssh/work-example.pub user@server.example.comOtherwise, give the .pub file to the server administrator through an approved channel. Never send the private-key file.
Select a private key for one connection with -i:
ssh -i ~/.ssh/work-example user@server.example.comSSH asks for the key's passphrase before it can use the private key.
Use ssh-agent
ssh-agent keeps unlocked identities available to SSH clients, so a passphrase-protected key does not need to be unlocked for every connection. Desktop and login environments often start an agent already. Check for its socket first:
printf '%s\n' "$SSH_AUTH_SOCK"If no agent is available, start one for the current shell:
eval "$(ssh-agent -s)"Add the key with a one-hour lifetime:
ssh-add -t 1h ~/.ssh/work-exampleList the public fingerprints of loaded identities:
ssh-add -lRemove one key when it is no longer needed:
ssh-add -d ~/.ssh/work-exampleRemove every loaded identity with:
ssh-add -DIf you started a dedicated agent for this shell, stop it when finished:
eval "$(ssh-agent -k)"The agent does not hand the private-key material to SSH, but a process that can access the agent socket may ask it to perform authentication operations while the key is loaded. Use passphrases, short agent lifetimes and a locked screen, and avoid forwarding the agent to remote systems unless there is a reviewed need.
Configure frequently used hosts
The per-user client configuration is ~/.ssh/config. Create the directory and file with restrictive permissions:
mkdir -p ~/.ssh
chmod 700 ~/.ssh
touch ~/.ssh/config
chmod 600 ~/.ssh/configAdd a memorable alias for the server:
Host work-example
HostName server.example.com
User user
IdentityFile ~/.ssh/work-example
IdentitiesOnly yes
UserKnownHostsFile ~/.ssh/work-example_known_hosts
Host *
ServerAliveInterval 15
ServerAliveCountMax 3You can now connect using only the alias:
ssh work-exampleThe settings mean:
Host work-exampledefines the name typed on the command line.HostNamesupplies the real DNS name or address.Userselects the remote account.IdentityFileselects the private key.IdentitiesOnly yesprevents unrelated agent keys from being offered to this server.UserKnownHostsFilekeeps this server's host identity in a dedicated file.ServerAliveInterval 15requests an encrypted keepalive after 15 seconds without received data.ServerAliveCountMax 3disconnects after three unanswered keepalives.
OpenSSH uses the first value it finds for most settings, so put specific Host blocks before the final Host * defaults. Host patterns also work when several servers share a configuration:
Host *.example.com
User myuser
IdentityFile ~/.ssh/work-example
IdentitiesOnly yesInspect the fully evaluated settings without making a connection:
ssh -G work-exampleFor connection troubleshooting, increase client logging temporarily:
ssh -v work-exampleAdd a second or third v only when more detail is needed. Debug output can include hostnames, account names and connection details, so review it before sharing.
The current OpenSSH manuals document the complete ssh command, ssh_config options, ssh-agent and ssh-add behaviour.